Before any roll we publish SHA-256(server seed) — a commitment we can't change later. Each roll is HMAC_SHA256(server seed, "client seed:nonce") reduced to 1–6. Tap Rotate & reveal to retire the seed — we reveal it, and every past roll becomes verifiable right in your browser. We never send the active seed early.
Runs entirely in your browser (Web Crypto). Recompute any revealed roll and confirm it matches the commitment and the value you saw.